Hacker News new | ask | show | jobs
by rmoriz 1605 days ago
As far as I learned, a couple of big companies are sending this kind of mail to every provider, partner or copyright owner of code that they could find.

I assume some developer/supplier used curl and provided a list of third party code and licenses they use.

In the aftermath of the log4j incident, companies now target everyone about this issue partly to learn about potential exposure that they are not aware yet, eg exploited infrastructure of depending services like newsletter or analytics services.

Yes, it's annoying and pointless to spam this mails to open source projects. But at least someone is now behind auditing the supply chain.

2 comments

It's a really dumb approach to vulnerability management for CYA. Spray and pray that the regulators are assuaged. It might even work as far as that goes.

But obviously, it's not a sound approach to actual vulnerability management.

I've read speculation that this is to cover their own asses with various regulations. Not sure if there's any weight behind this.